JobRaahGet matched free

Jobs

IT Security & Compliance Manager - Madrid Office

Sinclair Β· San Fernando de Henares, Spain Β· On-site

Posted Sep 7, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Sinclair is Hiring! Join Our Team as a IT Security & Compliance Manager πŸš€ We are currently recruiting for IT Security & Compliance Manager at our Madrid office. The ideal candidate will have experience in: ITGC SoD ERP Controls Location: Spain About Sinclair Founded in 1971, Sinclair is a global medical aesthetics organisation, that delivers an extensive product range. With an in-house commercial infrastructure, including manufacturing and a network of distributors in leading global markets, our products are sold in 55 countries worldwide. This is a great time to join Sinclair as we continue to increase our product range and expand into new markets and territories. Sinclair Values: βœ… Act with Integrity Consistently doing the right thing even when it’s the hard choice; 100% Compliance with all rules, standard operating procedures and guidelines βœ… Results-Driven Make a business impact in all you do, whether sales, efficiency, operational excellence; it should make a meaningful impact βœ… Innovation-Centered Redefining Aesthetics, we must be pioneering in how we do business; this can be in products, in service models, or strategy βœ… One Company, One Goal Working towards unified mission, we are all Sinclair and be seen by customers as one company in every way βœ… Own It! Be Accountable for your decisions, actions and consequences; Be Reliable to your customers and colleagues What You'll Be Doing: πŸ”Ή Audit response and readiness β€” primary β€’ Act as the single point of contact for external audit, group internal audit and finance control reviews: scope agreement, evidence, walkthroughs, management responses. β€’ Maintain one register of IT-related findings from every source, each with a named owner and a date. β€’ Report remediation status monthly to the Global IT Director, and at each audit cycle to Finance and to Legal & Compliance. β€’ Assemble the evidence base before it is asked for: application inventory, system owner matrix, access records, change records, backup and restore records. πŸ”Ή Internal controls, built from audit requirements β€’ Turn each agreed finding into a documented, repeatable control: control objective, control owner, frequency, evidence retained. β€’ Start with what is already known to be required β€” periodic user access review; segregation of duties in ERP and procure-to-pay; a named System Owner for every application. β€’ Design controls that can be operated at current headcount. Where one cannot be, record the compensating control and the accepted risk rather than writing a control that will fail its next test. β€’ Re-test what has been remediated, and close findings on evidence rather than assertion. πŸ”Ή Standing compliance duties β€’ Keep the IT policy set current β€” access, information security and acceptable use, continuity β€” and aligned to what is actually done. β€’ Review new and renewed software and services before any commitment is made: data location, processing terms, security, GxP impact,…